First published: Mon Dec 04 2023(Updated: )
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-35668.
The title of this vulnerability is 'In visitUris of Notification.java there is a possible way to display images from another user due to…'
In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
The vendor affected by this vulnerability is Google and the product affected is Android.
The severity of this vulnerability is high, with a severity value of 7.
You can find more information about this vulnerability at the following references: [link 1](https://source.android.com/security/bulletin/2023-12-01), [link 2](https://source.android.com/docs/security/bulletin/2023-12-01)